Demo

Legal

Privacy Policy

Last updated February 18, 2026

This policy describes how LendPathway (“we,” “us,” “our”) collects, uses, stores, shares, and protects your information when you use our platform, including information accessed through Google and Microsoft services.

What LendPathway Does

LendPathway is a document intelligence platform built for underwriters. It automates the extraction and analysis of financial documents so teams can make faster, more accurate funding decisions. Users upload or sync documents like bank statements and tax returns, and our platform processes them into structured financial data and analysis reports.

LendPathway is a multi-tenant B2B platform. Each organization's data is isolated at the application layer. Users can only access documents, reports, and settings that belong to their own organization. There is no cross-tenant data access.

What's Required and What's Optional

The only thing required to use LendPathway is signing in. Everything else is opt-in.

FeatureRequired?What it does
Sign-in (Google or Microsoft)RequiredVerifies your identity using your name and email. No access to mail, files, or anything else.
Gmail integrationOptionalEnables inbox search, document retrieval, and sending emails from within the platform.
Google Drive integrationOptionalEnables exporting reports and spreadsheets to your Drive.

Each optional integration requires its own separate OAuth 2.0 consent flow. You can use LendPathway without enabling any of them, and you can disconnect them at any time.

Sign-In

LendPathway uses Auth0 for authentication. You can sign in with your Google account or your Microsoft account (via Microsoft Entra).

When you sign in, Auth0 receives your name, email address, and profile picture from your identity provider to create and manage your LendPathway account. This is a standard identity handshake. LendPathway never sees or stores your Google or Microsoft password, and sign-in does not grant us access to your email, files, calendar, contacts, or any other account data.

Google Integrations

Gmail (Opt-In)

When you choose to connect your Gmail account, LendPathway requests read and send access to your Gmail. This powers several features within the platform.

Read access allows LendPathway to search your inbox, view email threads and message content, and download attachments for processing through our document analysis pipeline.

Send access allows LendPathway to send emails on your behalf when you initiate them from within the platform, such as document requests or status notifications. Both capabilities are granted together when you connect and both are removed when you disconnect.

ScopePurpose
gmail.readonlySearch inbox, read messages and threads, download attachments for document processing.
gmail.sendSend emails you initiate through the platform.
userinfo.emailIdentify your Google account for the connection.

How we use Gmail data. Gmail data is used to locate, retrieve, and process financial documents for underwriting analysis, and to send emails you initiate through the platform. We access message content and metadata to identify relevant documents and to power inbox and thread views within the app. Gmail data is accessed and processed on behalf of the user who connected their account and is used solely to provide features within LendPathway that the user has chosen to enable.

Google Drive (Opt-In)

When you choose to connect your Google Drive, LendPathway can export files to your Drive, including analysis reports and spreadsheet summaries. The integration also reads basic metadata (file names and IDs) of spreadsheets in the connected account to support export workflows.

ScopePurpose
drive.fileCreate and write files LendPathway exports to your Drive. Read metadata of spreadsheets for export features.
userinfo.emailIdentify your Google account for the connection.

What We Do Not Do with Google Data

  • We do not sell, rent, or transfer Google user data to third parties for advertising, marketing, or any purpose unrelated to providing the LendPathway service.
  • We do not use Google user data to serve ads, including retargeting or interest-based advertising.
  • We do not use Google user data to train AI or machine learning models.
  • We do not allow humans to read your Google user data except where you provide consent (such as when requesting technical support), where necessary for security purposes, or where required by law.

Google API Services Limited Use Disclosure

LendPathway's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Token Storage and Disconnection

When you connect a Google integration, your OAuth access and refresh tokens are stored securely in our database on the server side. When you disconnect an integration from within LendPathway, the associated tokens and connection records are permanently deleted from our systems.

Revoking Access

You can disconnect Gmail or Google Drive from within LendPathway at any time. You can also revoke access directly from your Google Account permissions page. Either action stops all data access and sending activity immediately.

Data We Collect

In addition to data accessed through integrations, LendPathway collects:

Account informationYour name, email address, and organization, provided during sign-up through Auth0 and your identity provider. Used to manage your account and communicate with you about the service.
Financial documentsBank statements, tax returns, and other financial files uploaded directly through the platform or retrieved via Gmail. These are the primary inputs to our analysis pipeline.
Analysis resultsStructured data and reports generated from your documents. Stored in your account for review, export, and sharing within your organization.
Usage dataBasic product analytics such as pages visited and features used. Collected to improve the platform. We do not use third-party advertising trackers.
CookiesLendPathway uses cookies that are strictly necessary for authentication and session management. We do not use cookies for advertising or behavioral tracking.

How We Use Your Data

We use the data we collect to operate and improve the LendPathway platform. Specifically:

  • To authenticate you and manage your account.
  • To process financial documents through our analysis pipeline and deliver results.
  • To power Gmail and Google Drive features you have opted into.
  • To send transactional communications about your account and the service.
  • To monitor platform performance and fix issues.
  • To comply with legal obligations.

We do not use your data for advertising, profiling, or any purpose unrelated to providing and improving the LendPathway service.

Data Isolation

All data in LendPathway is scoped to your organization. Every document, report, and setting is bound to the organization it belongs to. Users in one organization cannot see, search, or interact with another organization's data.

How We Protect Your Data

EncryptionAll data is encrypted in transit and at rest using industry-standard encryption provided by our cloud infrastructure providers.
InfrastructureLendPathway runs on managed cloud infrastructure with containerized, isolated services and network segmentation between components.
DatabaseApplication data is stored in managed PostgreSQL databases with encrypted connections and automated backups. Documents are stored in access-controlled S3-compatible object storage with server-side encryption.
Access controlsWe enforce role-based access control and least-privilege principles across all services, infrastructure, and team members. All user authentication is managed through Auth0 with support for multi-factor authentication.
MonitoringData access and processing events are logged for security and compliance review. Unusual activity is flagged for investigation.

AI Processing and External Providers

LendPathway uses third-party AI providers, including Google Gemini and OpenAI, to power document parsing and analysis. When a document is processed, relevant content is sent to these providers' APIs for analysis and the results are returned to our platform. These providers process data according to their enterprise agreements and do not use your data for model training under our terms with them.

All other application data (accounts, documents, reports, integration tokens) remains within our own infrastructure.

For organizations that require complete data residency control, LendPathway offers an on-premises deployment option. Self-hosted deployments keep all data and all processing, including AI, entirely within your own infrastructure.

Data Sharing

LendPathway does not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We share data only in the following circumstances:

Service providersWe use cloud infrastructure, authentication, and AI providers to operate the platform. These providers process data on our behalf under contractual obligations and do not have independent rights to your data.
At your directionWhen you export reports to Google Drive, share results with team members, or send emails through the platform, that activity is initiated and controlled by you.
Legal requirementsWe may disclose data if required by law, regulation, subpoena, or valid legal process.

Data Retention

We retain your data for as long as your account is active or as needed to provide the service. If you close your account or request deletion, we will delete your personal data and documents from our active systems. Some data may be retained in backups for a limited period before those backups are cycled out. We may also retain certain data as necessary to comply with legal obligations, resolve disputes, or enforce our agreements.

Your Rights

Depending on where you are located, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate personal data.
  • Request deletion of your personal data.
  • Request a copy of your data in a portable format.
  • Object to or restrict certain processing of your data.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days, or sooner where required by applicable law.

You can disconnect Google or Microsoft integrations from within LendPathway at any time. You can also manage connected apps directly from your Google or Microsoft account settings.

LendPathway complies with applicable data protection regulations including the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR) where applicable.

Do Not Sell or Share

LendPathway does not sell your personal information and has not sold personal information in the preceding 12 months. We do not share your personal information for cross-context behavioral advertising.

Children's Privacy

LendPathway is a business-to-business platform and is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child, we will take steps to delete that information promptly.

Changes to This Policy

We may update this policy to reflect changes in our practices or for legal reasons. When we make material changes, we will update the date at the top of this page and notify active users by email.

Questions about your data?

We take privacy seriously. Reach out any time at [email protected]